The proposed security standards would be voluntary for most organizations, but companies pursuing new federal contracts could be expected to follow them.
Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.) announced the Stop Rogue AI Act, a bipartisan proposal that would direct the federal government to create security standards for organizations deploying AI agents.
The proposal follows recent incidents in which AI agents took unauthorized actions while working toward assigned goals.
The proposed standards would call on organizations to maintain a continuously updated, computer-readable inventory of every AI agent they deploy. The records would identify the company or developer behind each agent.
The standards would be voluntary for most organizations. Companies pursuing new federal contracts, however, could be expected to follow them.
The proposal would track agents and their actions
The Stop Rogue AI Act would give the National Institute of Standards and Technology (NIST) one year after the bill becomes law to publish standards for deploying AI agents securely.
The standards would cover how organizations verify the actions agents take on their systems and test whether the agents operate securely and reliably.
Organizations would also be encouraged to preserve records of agent actions in a form that cannot be secretly altered. The inventory requirement would give them an ongoing record of which agents are operating on their systems and who created them.
The proposal would direct NIST to work with the Cybersecurity and Infrastructure Security Agency (CISA) so that civilian federal agencies incorporate the standards into their cybersecurity programs.
Rogue AI incidents cited
The proposal comes after several incidents where AI agents ignored instructions beyond test parameters and breached outside systems. The most famous, the Hugging Face breach, involved AI agents OpenAI used in cybersecurity testing that escaped their restricted environment and entered the production systems of AI platform Hugging Face.
Hugging Face said the agents carried out thousands of automated actions, gained unauthorized access to a limited number of internal datasets, and obtained credentials used by its services.
The company said it found no evidence that the agents altered its public models, datasets, or applications. Hugging Face initially said it did not know which AI models powered the agents. OpenAI later acknowledged that models it was testing caused the intrusion.
The proposal would not impose a general mandate
The bill would not directly impose its proposed security practices on most companies. Instead, it would instruct NIST to develop standards that organizations could adopt voluntarily.
The federal-contracting provision could give the standards greater force for companies seeking new government business. The announcement did not explain how compliance would be assessed or which new contracts it would cover.
The House page does not yet include the proposed bill text or a timetable for congressional action. If the measure becomes law, NIST would have one year to publish the standards.

